The repository has one maintainer, no commits in three months, and no security policy. The package is licensed, documented, not deprecated, and its release notes cover Statamic 6 support.
61%
Total Score
67
100
88
67
Only one registry account has publishing access. That is a thin publishing base for a user-owned project and increases the risk that maintenance depends on one person.
The package has only three releases over roughly three years, with a median interval of about 17 months and one release in the last year. This indicates a slow maintenance cadence, though the latest release is recent.
There were zero commits and zero active maintainers in the last three months. For a small package this may reflect release-driven maintenance, but it still provides weak evidence of ongoing development capacity.
The repository uses Composer build tooling, but no security scanning tools were detected. The absence of scanning is a modest transparency and hygiene gap.
The repository has no security policy. This does not show a vulnerability, but it leaves the process for reporting and handling security issues unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
pixelfear/composer-dist-plugin Version ^0.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.